Nihilist cipher
Polybius coordinates and a repeating keyword, added together as ordinary arithmetic.
The groups above
The square is keyed on ZEBRAS and the additive keyword is RUSSIAN. Two groups in the output run to three digits, 106 and 104, where every other group has two. That is the cipher leaking.
Making a group
Message and keyword are looked up in the same 5 by 5 square, each letter becoming a two-digit number, row then column. The top-left cell is 11 and the bottom-right is 55, so in the loaded square Z is 11 and A is 15. The keyword numbers repeat underneath the message numbers and the two are added as plain integers. Decryption subtracts. I and J share a cell unless the control beside the square key says otherwise.
Russia in the 1880s
This came out of the revolutionary underground the Tsarist police spent the decade chasing. The People’s Will had already gone after Alexander II with dynamite inside the Winter Palace in February 1880: a charge built up under the dining room by Stepan Khalturin, a carpenter employed there who carried the sticks in a few at a time and slept on them. It killed eleven guardsmen. The Tsar’s dinner guest was late, the meal was put back, and the room was empty. They killed him in the street in March 1881. Conspirators under that kind of surveillance wanted a cipher they could work with a pencil, memorize, and teach in an afternoon.
What the numbers give away
The sums are never reduced, so the arithmetic shows through. A group runs from 22 to 110. Anything above 100 needs two letters that both sit in the bottom row of the square, since no other pair of rows adds up to ten tens. No group ever ends in 1: the two column digits total between 2 and 10, and a total of 10 pushes a ten across and leaves a zero behind. That is a lot of structure to hand over before anyone has guessed a letter.
The keyword is the worse problem. It repeats, so every group in the same key position carries the same constant. Split the message by the key length and each pile is a simple substitution on the square, which letter frequencies finish off, and finding the key length is the Kasiski problem that broke Vigenere. Nothing here fractionates: one plaintext letter makes one group, so the frequencies come through the addition intact and wait to be counted.
Related
The Polybius square supplies the numbers this cipher adds up. Vigenere has the same repeating-key weakness in letters rather than numbers, and the tap code is the knock alphabet the same underground used through cell walls.